When integrating components sourced from third parties in products with digital elements during the design and development phase, manufacturers should, in order to ensure that the products are designed, developed and produced in accordance with the essential cybersecurity requirements set out in this Regulation, exercise due diligence with regard to those components, including free and open-source software components that have not been made available on the market. The appropriate level of due diligence depends on the nature and the level of cybersecurity risk associated with a given component, and should, for that purpose, take into account one or more of the following actions: verifying, as applicable, that the manufacturer of a component has demonstrated conformity with this Regulation, including by checking if the component already bears the CE marking; verifying that a component receives regular security updates, such as by checking its security updates history; verifying that a component is free from vulnerabilities registered in the European vulnerability database established pursuant to Article 12(2) of Directive (EU) 2022/2555 or other publicly accessible vulnerability databases; or carrying out additional security tests. The vulnerability handling obligations set out in this Regulation, which manufacturers have to comply with when placing a product with digital elements on the market and for the support period, apply to products with digital elements in their entirety, including to all integrated components. Where, in the exercise of due diligence, the manufacturer of the product with digital elements identifies a vulnerability in a component, including in a free and open-source component, it should inform the person or entity manufacturing or maintaining the component, address and remediate the vulnerability, and, where applicable, provide the person or entity with the applied security fix.
Recital 34
Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026
European Commission Interpretation
Guidance of 27 July 2026The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.
Section 7.3External dependencies vs. due diligence for components
Two complementary obligations: the risk assessment (Art. 13(2)) also covers external risks — back-ends, infrastructure, environment — to be mitigated through product-level measures; the CRA does not regulate how external infrastructure is operated. Due diligence (Art. 13(5)) concerns integrated third-party components: the manufacturer defines what the component must deliver and verifies it in a risk-based manner.
Key takeaways
- Examples of product-level mitigation of external risks: cryptographic authentication of remote commands, integrity verification of configuration changes, secure fail states when external services become unavailable.
- Due diligence evidence: the component manufacturer's technical specifications and security documentation, conformity/assurance documentation, and where appropriate the manufacturer's own tests.
- Integrated third-party components belong in the risk assessment but are treated as externally supplied parts whose properties are verified upon integration (recital 34).
In practice
Split your risk list into two columns: external dependencies (third-party back-ends, networks, environment) → mitigate at product level, e.g. authenticated remote commands and secure fail states; integrated third-party components → define requirements and collect evidence (manufacturer documentation, certificates, your own tests). How the external provider runs its operations is not your CRA problem.
EU Commission Guidance (C(2026) 5252 final) — The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.
Related Articles
(1)This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex